2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2020-3374CRITICAL9.9A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem...
CVE-2020-16165CRITICAL9.8The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to t...
CVE-2020-16163CRITICAL9.1An issue was discovered in RIPE NCC RPKI Validator 3.x before 3.1-2020.07.06.14.28. RRDP fetches proceed even with a lac...
CVE-2020-14158CRITICAL9.1The ABUS Secvest FUMO50110 hybrid module does not have any security mechanism that ensures confidentiality or integrity ...
CVE-2020-3699CRITICAL9.8Possible out of bound access while processing assoc response from host due to improper length check before copying into ...
CVE-2020-3698CRITICAL9.8Out of bound write while QoS DSCP mapping due to improper input validation for data received from association response f...
CVE-2020-3688CRITICAL9.8Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapd...
CVE-2020-3671CRITICAL9.8Use-after-free issue could occur due to dangling pointer when generating a frame buffer in OpenGL ES in Snapdragon Compu...
CVE-2020-7699CRITICAL9.8This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP r...
CVE-2020-14316CRITICAL9.9A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's...
CVE-2020-15588CRITICAL9.8An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled serve...
CVE-2020-15086CRITICAL9.8In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered ...
CVE-2020-4567CRITICAL9.8IBM Tivoli Key Lifecycle Manager 3.0.1 and 4.0 uses an inadequate account lockout setting that could allow a remote atta...
CVE-2020-2076CRITICAL9.8SICK Package Analytics software up to and including version V04.0.0 are vulnerable to an authentication bypass by direct...
CVE-2020-14487CRITICAL9.8OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly ...
CVE-2020-9691CRITICAL9.6Magento versions 2.3.5-p1 and earlier, and 2.3.5-p1 and earlier have a dom-based cross-site scripting vulnerability. Suc...
CVE-2020-7698CRITICAL9.8This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endp...
CVE-2020-7697CRITICAL9.8This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affec...
CVE-2020-5377CRITICAL9.1Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. ...
CVE-2020-15623CRITICAL9.8This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e1...
CVE-2020-15615CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e...
CVE-2020-15614CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e...
CVE-2020-15613CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e...
CVE-2020-15612CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e...
CVE-2020-15611CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now